CVE-2021-37147: Request Smuggling - LF line ending
Improper input validation vulnerability in header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-37147?
CVE-2021-37147 is an improper input validation vulnerability in header parsing of Apache Traffic Server.
How does CVE-2021-37147 affect Apache Traffic Server?
CVE-2021-37147 allows an attacker to smuggle requests, affecting Apache Traffic Server versions 8.0.0 to 8.1.2 and 9.0.0 to 9.1.0.
How severe is CVE-2021-37147?
CVE-2021-37147 has a severity score of 7.5, which is classified as high.
What is the remedy for CVE-2021-37147 on Debian Linux?
The remedy for CVE-2021-37147 on Debian Linux is to update to the specified versions: 8.0.2+ds-1+deb10u6, 8.1.7-0+deb10u2, 8.1.7+ds-1~deb11u1, 9.2.0+ds-2+deb12u1, or 9.2.2+ds-1.
Are there any references for CVE-2021-37147?
Yes, you can find references for CVE-2021-37147 at the following links: [1] https://lists.apache.org/thread/k01797hyncx53659wr3o72s5cvkc3164, [2] https://www.debian.org/security/2022/dsa-5153, [3] https://www.openwall.com/lists/oss-security/2021/11/02/11.